Produksi berjalan di Hetzner Kubernetes (K3s) dengan Argo CD.
Pipeline
Push main → GitHub Actions (lint / build / docker)
→ ghcr.io/halort/<service>:<sha>
→ CI pin tag image di deploy/.../kustomization.yaml
→ Argo CD sync
| Lapisan | Lokasi |
|---|---|
| Terraform (Hetzner + Cloudflare) | halort-infra/terraform/ |
| Bootstrap K3s | halort-infra/bootstrap/ |
| Addon platform (ingress, cert-manager, …) | halort-infra/gitops/platform/ |
| Argo Applications | halort-infra/gitops/root/ |
| Manifest per layanan | setiap repo deploy/kubernetes/apps/<service>/ |
Argo UI: https://argocd.halort.com
DNS
npm run dns:k8s di halort-infra upsert record A Cloudflare untuk host produksi (termasuk docs.halort.com) dan *.halort.com → Hetzner LB. Lihat Ops/DNS and Domains.
Secrets
Secret runtime tetap di cluster (bukan Git): mis. halort-platform-runtime-env, halort-web-runtime-env, halort-notification-runtime-env, secret pull GHCR. Helper: make sync-ghcr-pull, make sync-platform-secrets, dll. Lihat Ops/Secrets Overview.
Dashboard CI
Dari halort-infra: npm run ci memantau Actions + Argo untuk web, platform-web, platform, design-system, docs, notifications, infra.